CVE-2018-18808
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability that may allow any users with domain save privileges to gain superuser privileges. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| TIBCO Software Inc. | TIBCO JasperReports Server | unspecified <= 6.3.4 (affected), 6.4.0 (affected), 6.4.1 (affected), 6.4.2 (affected), 6.4.3 (affected), 7.1.0 (affected) |
| TIBCO Software Inc. | TIBCO JasperReports Server Community Edition | unspecified <= 7.1.0 (affected) |
| TIBCO Software Inc. | TIBCO JasperReports Server for ActiveMatrix BPM | unspecified <= 6.4.3 (affected) |
| TIBCO Software Inc. | TIBCO Jaspersoft for AWS with Multi-Tenancy | unspecified <= 7.1.0 (affected) |
| TIBCO Software Inc. | TIBCO Jaspersoft Reporting and Analytics for AWS | unspecified <= 7.1.0 (affected) |
References & Technical Advisories
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | TIBCO Software Inc. · Vendor · USA |
| Reserved | 2018-10-29T00:00:00 |
| Published | 2019-03-07T22:00:00 |
| Patch Date | 2019-03-06 |
| Last Updated | 2024-09-16T19:46:17 |
Community Chatter & Buzz